Разработчики призвали срочно исправить критическую уязвимость в GitLab
Reported exploitedGitLab CEGitLab EEOur summary
GitLab has released patches for a critical path traversal vulnerability identified as CVE-2026-85706, which carries a maximum CVSS score of 10. This flaw allows unauthenticated attackers to read arbitrary files on the server through the repository commits API, affecting GitLab Community Edition and Enterprise Edition versions from 18.7 up to 19.3.1.
Security researchers have observed active exploitation attempts in the wild shortly after the vulnerability was disclosed, making immediate remediation essential. In addition to CVE-2026-85706, the update also addresses CVE-2026-87719, a high-severity insecure deserialization issue in GitLab EE's GraphQL subscription serializer. Administrators are advised to upgrade to fixed versions 19.3.2, 19.2.6, or 19.1.8 immediately to protect against potential data exfiltration.
Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.